Courseiva
mediumMultiple ChoiceObjective-mapped

CRISC Practice Question: During a review of third-party vendor risks, the…

During a review of third-party vendor risks, the risk team identifies that a cloud service provider's data center is located in a country with unstable political conditions. What should the risk practitioner do FIRST?

⚠ Common exam trap

The trap here is that candidates may jump to a risk treatment action (accept, mitigate, or terminate) without first completing the foundational step of documenting and assessing the risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Document the risk and assess its potential impact.

The risk practitioner's first step should be to document the identified risk and assess its potential impact on the organization. This aligns with the CRISC framework's emphasis on risk identification and assessment before any treatment decisions are made. Without a thorough impact assessment, the organization cannot determine whether the risk is acceptable, requires mitigation, or warrants contract termination.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Document the risk and assess its potential impact.

    Why this is correct

    Proper risk management starts with documentation and assessment.

  • Accept the risk based on the vendor's SLA.

    Why it's wrong here

    Acceptance requires full understanding; SLA may not cover political risks.

  • Request the vendor to move data to another region.

    Why it's wrong here

    Action without impact assessment is premature.

  • Terminate the contract immediately.

    Why it's wrong here

    Termination is a drastic measure; assessment should come first.

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.